 RedsMan
join:2005-04-13
| Firewall Rules and WRT54GS Sveasoft firmware
Hey all,
I'm struggling to get to grips with how to manage / control / know exactly what rules are in place with respect to the firewall functionality on the WRT54GS / WRV54G / WAG54G models.
While the web interfaces offer admin of this - my only exposure to configuring firewall rules is on a Cisco PIX via the command line and I trying to get to the same point on any or all of the models above.
Right now I am looking at the WRT54GS in particular on account of the Sveasoft firmware that seems to allow more access to the device in terms of telnet / CLI access and control. However, I'm not familiar with this firmware or the details of its added funtionality.
Does anyone know if the Sveasoft alternative firmware versions (I think I would be looking at Alchemy for the GS) give me the ability to completely customise firewall rules on the WRT54GS ?? I've seen mention of firewall scripts though I would like to know to what extent might these be customisable. Is it iptables under the hood ??
Just to explain what I want to do, if it might help (as cheaply as possible might I add) - is to allow access back and forward between a couple of different sites for basic services, http, ftp server etc. I would like to have specific rules on the WRT54GS at either site that would only allow access to the inside LAN service destinations (via port forwarding on the router) based on a particular (DDNS name) source IP address.
So to get to the point:
1) Does the Sveasoft firmware allow me this level of control over the firewall rules via the command line ??
2)Could I put such rules in place using dynamic (DDNS) IPs at both sites ?? - So the rule would be allowing access based on the source DDNS name (reverse lookup on source IP). Is this possible ?
I have been considering a VPN approach also (thanks to help from DocLarge and others) but also think the WRT54GS approach at each end might support my short term needs if I can get the firewall rules I need in place - and the price is right on these boxes.
Thanks in advance to any Sveasoft experts out there.
Cheers, RedsMan |